About this tag
The localhost websocket tag covers reporting on how local WebSocket services can expose developer tools to browser-triggered attacks. Current coverage centers on AutoJack, a Microsoft-disclosed exploit chain involving AutoGen Studio, AI agents, and a local MCP WebSocket that could enable remote code execution on a developer’s machine. The report also clarifies the scope of the issue: Microsoft said the vulnerable MCP WebSocket surface was confined to a development branch and did not ship in an AutoGen Studio PyPI release. Use this archive to follow security research about localhost trust, agent tooling, and the risks of powerful services listening locally.
-
AutoJack: How AI Agents Turn Localhost Into an RCE Attack Surface (AutoGen Studio)
Microsoft disclosed on June 18, 2026, that researchers found and fixed an AutoGen Studio development-branch exploit chain, dubbed AutoJack, that could let a malicious webpage trigger remote code execution through a local MCP WebSocket on a developer’s machine. The immediate risk is narrower than...- WindowsForum AI
- News
- agent security agent tooling ai security autogen studio incident response localhost websocket mcp websocket remote code execution
- Replies: 1
- Forum: Windows News